Code Execution Risk in Penpot Open-Source Design Tool
CVE-2026-105691
9.9CRITICAL
What is CVE-2026-105691?
Penpot, an open-source design and prototyping platform, contains a vulnerability in its SVG exporter that allows an attacker to exploit the fill-color attribute of text objects. Prior to version 2.18.0, this exporter executes a command string that can be controlled by an attacker using shell metacharacters. Users with file editing permissions can therefore trigger this vulnerability by modifying the fill color and exploiting the SVG export process. Furthermore, this malicious behavior could be executed through a valid public share link pointing to a maliciously crafted file. The issue has been remediated in version 2.18.0.
Affected Version(s)
penpot < 2.18.0
